---
title: "Policy management is now generally available"
description: "Following early access, policy management - Cloudsmith's policy-as-code system for enforcing rules across your software supply chain - is now generally available across the web app, API, and Terraform provider."
canonical_url: "https://cloudsmith.com/changelog/policy-management-is-now-generally-available"
last_updated: "2026-08-12T11:13:25.435Z"
---
# Policy management is now generally available

Following early access, policy management - Cloudsmith's policy-as-code system for enforcing rules across your software supply chain - is now generally available across the web app, API, and Terraform provider. This includes:

- **Custom policies:** write your own logic in Rego, Cloudsmith's policy language, tailored to your specific security and compliance requirements
- **Always-on enforcement:** policies are evaluated on package upload, and re-evaluated automatically as policies or threat intelligence changes
- **Cooldown policies:** hold new package versions back from consumers for a set window before they're trusted
- **Policy templates:** pre-built starting points so you don't need to write Rego from scratch
- **Decision logs:** a full audit trail of every policy evaluation, viewable in the web app or downloadable via API

```json
{
  "_key": "36d897a63253",
  "_type": "image",
  "alt": "Templated Rego policies in the Cloudsmith web app",
  "asset": {
    "_createdAt": "2026-08-12T09:18:35Z",
    "_id": "image-1f549d9cbf76983b9cffcdc8c76699e1192958e5-1678x1072-png",
    "_rev": "a1bfJzYayZiLiZqoYGvPna",
    "_type": "sanity.imageAsset",
    "_updatedAt": "2026-08-12T09:18:35Z",
    "assetId": "1f549d9cbf76983b9cffcdc8c76699e1192958e5",
    "extension": "png",
    "metadata": {
      "_type": "sanity.imageMetadata",
      "blurHash": "V6SPb6~WIo-;9Z.8IpWBjYayE2M_M{kCoM~pxYWBWrae",
      "dimensions": {
        "_type": "sanity.imageDimensions",
        "aspectRatio": 1.5652985074626866,
        "height": 1072,
        "width": 1678
      },
      "hasAlpha": true,
      "isOpaque": true,
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAANCAYAAACpUE5eAAAACXBIWXMAABYlAAAWJQFJUiTwAAABz0lEQVR4nI2T647bIBSE8/5PWalK28SOud8vX3Vwsspu+2ORRhgDw5xhuPx5GO7KshuHdhET0oIOCeUSxzexm8h101wO41HGoazDhUgqldIapXVS6cTSFnLt5DbO/oW3cUiVu3JcjI84UWMDyvr1XWqn90nOA+/rWpxro/ZB65NSZK5TqowHfcw1vykvhAkXG8pXdltQrhLyoNSJ951jzygTsT4QUqaUjncddWSsS8RUqK0Tc+O6L4UJnzo2DlQY6DAIeVIahNg5VOIwAeNO9bk0QihoFdAm4KUi+Zcr181xWYvqoDY+0Aa0Di4ONpNR9lToohAWsvc4pbDW46NY1Jb3dylZFokPc7Las6MPIezc9alQL4VxESbvsYdCm/MiS6nkUtn0fwhfbYxJigmjDOaVgFzW7ftYl6/GxeWreChWnAqDEHbmO+OcjD7IzmO3DaPNc2OjtokOnfvTWxfSKjfmTwq/EArnmJRc8OLTM5+iRKrxqXHYuKKmXcCGiIuZTXK4FLaT8Cskc7WNj/xJ3poc1AZpXYSEvq7DJKuLUMIcUlmm5voGKeP5SgSy+SR4QeafyBUbMvKMLz9vO7eH5n78i9vDfA+H5feu+fFr5y+M8vExnjTBagAAAABJRU5ErkJggg==",
      "palette": {
        "_type": "sanity.imagePalette",
        "darkMuted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#6f2933",
          "foreground": "#fff",
          "population": 0,
          "title": "#fff"
        },
        "darkVibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#943844",
          "foreground": "#fff",
          "population": 0.01,
          "title": "#fff"
        },
        "dominant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#477ddd",
          "foreground": "#fff",
          "population": 0.06,
          "title": "#fff"
        },
        "lightMuted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#a4b1d7",
          "foreground": "#000",
          "population": 0.04,
          "title": "#fff"
        },
        "lightVibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#89bcfc",
          "foreground": "#000",
          "population": 0.01,
          "title": "#fff"
        },
        "muted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#7d7f9d",
          "foreground": "#fff",
          "population": 0.04,
          "title": "#fff"
        },
        "vibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#477ddd",
          "foreground": "#fff",
          "population": 0.06,
          "title": "#fff"
        }
      },
      "thumbHash": "/fcBBIBdB1RWd5hDhJtuMLFSBA=="
    },
    "mimeType": "image/png",
    "originalFilename": "policyAsCodeTemplates.png",
    "path": "images/rafvlnhi/production/1f549d9cbf76983b9cffcdc8c76699e1192958e5-1678x1072.png",
    "sha1hash": "1f549d9cbf76983b9cffcdc8c76699e1192958e5",
    "size": 233681,
    "uploadId": "ab5f7215faee0a478663f9e02fa829077cebc0f7",
    "url": "https://cdn.sanity.io/images/rafvlnhi/production/1f549d9cbf76983b9cffcdc8c76699e1192958e5-1678x1072.png"
  },
  "link": {
    "_type": "link",
    "href": null,
    "openInNewTab": false
  },
  "markDefs": null
}
```

## **Continuous risk detection and policies**

In addition to writing policies that act on package metadata, you can also write policies using Cloudsmith's continuous risk detection, which is also [generally available](https://cloudsmith.com/changelog/continuous-risk-detection-is-now-generally-available).

```json
{
  "_key": "5b8b951b15e8",
  "_type": "image",
  "alt": "Continuous risk detection in the Cloudsmith web app",
  "asset": {
    "_createdAt": "2026-08-12T09:19:23Z",
    "_id": "image-d80dcbcca25e340612e577ad272ed80ad154adc5-1800x1282-png",
    "_rev": "DYQzwRbvxyR3ukdwtHbTCH",
    "_type": "sanity.imageAsset",
    "_updatedAt": "2026-08-12T09:19:23Z",
    "assetId": "d80dcbcca25e340612e577ad272ed80ad154adc5",
    "extension": "png",
    "metadata": {
      "_type": "sanity.imageMetadata",
      "blurHash": "VH9QK,tkIoRPIU0KRP%2tR%M~WtQI:V@M{9ZV@xHozt7",
      "dimensions": {
        "_type": "sanity.imageDimensions",
        "aspectRatio": 1.4040561622464898,
        "height": 1282,
        "width": 1800
      },
      "hasAlpha": true,
      "isOpaque": true,
      "lqip": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAOCAYAAAAvxDzwAAAACXBIWXMAAAsTAAALEwEAmpwYAAACT0lEQVR4nI2RS09TQRSA+xfs7X3Mfb/a0tuClJckxoVLKIkRZKUrEFp88krRsPEvsFGMRkmM0VbQrZEQftpnZorQBo0svsw95858c86ZnDN8E4lenuBaMoqW1rEqU4jsBnppnHxaRyuOYVYmMYemKBTH1D6Zl7GoTmOUJ9GSOvlklJw9NI5TmcBIr5MPMrQww4iH0eMaWlhVcSGqosdV9KiGFmTkg4paZazHNfVfxpKcCIo4URnLTymIAM3yLyPz4i/5PuRZ3Q7JmcLFcnxM20M3HQqmfQnNsNF0cYbdhxjIFQyHnGG5mI6PcAOE62M6HqbtYgiJo9Cl+PzwvykYNjnTDhFejBsmeEGC5QbolqsqkyIlM/4v0/4ILSfG9lPcMMX1Eyw7RDfdXptXFGmDwhDbi/HCFC9IcbwY4USYtq8qHZzfVVoWHsIJVLthXCKIS/hRET9Msd0QOWO5cQD1ABdoAxXavjoohVIiV9m6XB03Ql4oN+Z1cUGh71u/kJ1X6HghaSmjNjJGbaROtVYnq41SyUYolTOSpEwYFc+JzujFKbZ8SNNRM89JaxCmzMzOsb6+SfvFrmKn/ZKt5mOeLtzn0dwircY9Wo2FHrPztGbmWWsssNyY5/b0LVwv6gllucVSxrMnz/lx9J1fxyccn5xyenzCz/efONp6RbfZprO2Q6fVVnxd2eLL0gbdlW0OWtus3lkkiUuqdSVM0iGWl1b5+OGATveQzrcjDruHfN57zbv1XfabW+y3+ljd4M3Ddd42N9lrbvBg7q4agRT+BtmwptW+V9PuAAAAAElFTkSuQmCC",
      "palette": {
        "_type": "sanity.imagePalette",
        "darkMuted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#344c5d",
          "foreground": "#fff",
          "population": 0.02,
          "title": "#fff"
        },
        "darkVibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#8c2c34",
          "foreground": "#fff",
          "population": 0,
          "title": "#fff"
        },
        "dominant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#b2bcc1",
          "foreground": "#000",
          "population": 0.05,
          "title": "#fff"
        },
        "lightMuted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#b2bcc1",
          "foreground": "#000",
          "population": 0.05,
          "title": "#fff"
        },
        "lightVibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#fc94ac",
          "foreground": "#000",
          "population": 0,
          "title": "#fff"
        },
        "muted": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#6e8195",
          "foreground": "#fff",
          "population": 0.02,
          "title": "#fff"
        },
        "vibrant": {
          "_type": "sanity.imagePaletteSwatch",
          "background": "#cc3c5c",
          "foreground": "#fff",
          "population": 0.01,
          "title": "#fff"
        }
      },
      "thumbHash": "ywcKDYRpV3dwioqPdkaXimeAZwWp"
    },
    "mimeType": "image/png",
    "originalFilename": "continuousRiskDetectionEditor.png",
    "path": "images/rafvlnhi/production/d80dcbcca25e340612e577ad272ed80ad154adc5-1800x1282.png",
    "sha1hash": "d80dcbcca25e340612e577ad272ed80ad154adc5",
    "size": 605459,
    "uploadId": "544b0dfc58cf02d605f6e5eb0dd87505f83b9392",
    "url": "https://cdn.sanity.io/images/rafvlnhi/production/d80dcbcca25e340612e577ad272ed80ad154adc5-1800x1282.png"
  },
  "link": {
    "_type": "link",
    "href": null,
    "openInNewTab": false
  },
  "markDefs": null
}
```

## Getting started

Policy management is available as an add-on for Ultra and Enterprise plans. Reach out to your account team to get started.

A separate set of baseline standard policies is included in both plans: CVE, license, package deny, and — newly added — malware policies. The package search field is no longer available when creating vulnerability and license policies in the web app, API, or Terraform. Existing policies using it are frozen and cannot be edited, but remain in place and continue to evaluate.

Policy management and baseline standard policies now live together under **Policies** in the main navigation:

```json
{
  "_key": "a4d4b263133b",
  "_type": "wistiaVideo",
  "id": "3y4ow1hsrj",
  "markDefs": null,
  "thumbnail": {
    "_type": "image",
    "asset": {
      "_ref": "image-4d590f6ffaf843f868beb28c43453dea3800d1e8-1063x598-png",
      "_type": "reference"
    }
  },
  "title": "Creating policies as code in the Cloudsmith web app"
}
```

For more details about Cloudsmith policy management, see:  


- [Policy management](https://docs.cloudsmith.com/policy-management)
- [Terraform provider: Policy as code](https://docs.cloudsmith.com/developer-tools/terraform-provider#policy-as-code)
